Scriptless Social Sharing

Scriptless Social Sharing has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

Every one of the 2 issues recorded for Scriptless Social Sharing has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Scriptless Social Sharing is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Scriptless Social Sharing vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2025-39529

Scriptless Social Sharing <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Scriptless Social Sharing banner
Latestv3.3.1

Scriptless Social Sharing

Robin Cornett

Author

Robin Cornett

5.0(69)
100/100
Last Updated
2025-07-19 (1y ago)
Active Installs
10,000+
Downloads
200,281
Requires WP
6.2+
Requires PHP
7.4+
Tested up to
WP 6.8.8
Created
2016-03-01 (11y ago)

Scriptless Social Sharing is a wee plugin to add buttons to your posts/pages, to make it easier for your readers to share your content on social networks. The sharing links use the most basic methods provided by each network. There is no JavaScript, nothing fancy included in this plugin, so if you want fancy, this is not the plugin you’re looking for. It just builds a set of links. The sharing buttons are accessible–even if you choose the “Icons Only” button styles, the network names are still part of the buttons, just hidden in an accessible-ready manner. There is a small settings page, so you can make decisions about which content types should have sharing buttons and where, what buttons should be added, and whether or not to use the plugin’s styles. Beyond that, developers may like to make use of filters throughout the plugin. Banner/icon image credit: Ryan McGuire on Gratisography.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C